NIST catalogs so many vulnerabilities that it can only assign severity scores to the highest priority threats


  • NIST Changes National Vulnerability Database Enrichment Process Due to Increase in CVE Submissions
  • 263% increase since 2020; priority now given to KEV records, federal software, and critical software under EO 14028
  • Other CVEs are considered “lowest priority”, but users can request enrichment via email if necessary

The number of reported vulnerabilities has increased so much that it forced the National Institute of Standards and Technology (NIST) to change how it ‘enriches’ each entry.

Until now, NIST would take a basic CVE record and add structured analysis to make it more useful in the National Vulnerability Database (NVD). It usually includes severity scoring (CVSS), affected products (CPE), vulnerability classification (CWE) and additional metadata.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top